BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Legacy DeFi Contracts Targeted in $27M Hack Spree via AI bot

Integer-overflow exploit allowed mint-and-drain of ~$26M in TRU as on-chain bots and flash-loan attacks hit legacy DeFi — Futureswap attacked twice; researchers urge audits or deprecation.

  • Truebit suffered an integer-overflow exploit that let an attacker mint tokens and withdraw about $26 million.
  • On-chain bots quickly replicated the Truebit exploit, accelerating losses and market impact.
  • Futureswap was hit twice in a month, losing about $400,000 in a recent attack and roughly $1 million in total this month.
  • Several older DeFi contracts remain vulnerable; security researchers urge teams to deprecate or re-audit legacy code.
  • Attackers used both a minting vulnerability and a flash-loan–powered governance exploit in recent incidents.

On Thursday, the verification-layer protocol Truebit suffered a major smart-contract exploit that let an attacker mint large amounts of TRU tokens and withdraw funds. The project warned the public not to interact with the affected contract in a post on X announcing the incident.

- Advertisement -

Security analysis shows the contract had an integer-overflow vulnerability, a coding error where arithmetic exceeds a storage limit and wraps around, allowing the attacker to “infinite mint” tokens. The attacker burned the minted TRU and withdrew 8,535 ETH, about $26 million, and the TRU price fell to zero.

The vulnerable code dated back nearly five years and the contract once held almost 44,000 ETH, according to a post on X noting its prior balance. A security researcher observing the aftermath said on X that “fuzzing bots are eating this up like piranhas.” (see the comment here). Fuzzing bots are automated scanners that probe contracts for weaknesses.

Earlier today, an apparent follow-up hit leveraged-trading platform Futureswap on Arbitrum. Alerts from on-chain monitors noted the unverified contract lost just over $400,000 in the latest incident, bringing the month’s total losses to about $1 million, as flagged in a report on X by Defimon Alerts.

Futureswap was also targeted in December by a governance attack that used tokens borrowed via a flash loan — a short-term loan that must be repaid within one transaction — to pass a malicious proposal. That earlier attack was detailed on X here, with estimated losses of at least $550,000 noted here.

- Advertisement -

Pseudonymous ex-Yearn security researcher storming0x urged teams to act, recommending they “either deprecate/sunset or reaudit” legacy contracts, “implement preventive actions”, and telling users to “withdraw from old contracts.” Their full comments are on X here and here. They warned, “It’s going to keep happening.”

Several projects that were prominent during the 2020–2022 DeFi boom — including Ribbon Finance, Rari Capital and Yearn — had contracts targeted in December, prompting speculation that attackers are reassessing older code. The recent cases underline calls for teams to audit or retire outdated contracts to protect users.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Bitcoin Pullback from $79.5K Tests Key $80K Support Levels

Bitcoin retreated from a high of $79,485, falling just shy of the $80,000 milestone...

Bits of Gold Gets Israeli Nod for Shekel-Pegged Stablecoin

Israel’s Capital Market, Insurance and Savings Authority has approved the BILS stablecoin, pegged 1:1...

SanDisk, Western Digital price targets lifted on AI demand

Cantor Fitzgerald analyst C.J. Muse significantly raised price targets for SanDisk (SNDK) and Western...

Robinhood phishing scam used authentic emails to attack

Highly convincing phishing emails were sent to Robinhood customers this weekend, appearing to come...

Checkmarx Data Leaked on Dark Web Following Attack

Checkmarx confirms stolen data from its GitHub repository was published on the dark web.The...

Must Read

How Cryptocurrency Works For Beginners?

Welcome to the world of cryptocurrency! If you're new to this exciting and rapidly evolving landscape, you might feel like Alice in Wonderland, exploring...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading